ARS-Rescue Rooter

Identity Security Engineer

ARS-Rescue Rooter United States

Consumer Services · 5,001-10,000 employees

Jul 01
Remote security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Identity Security Engineer will administer and secure identity services including Okta, Entra ID, and CyberArk while implementing SSO, MFA, and lifecycle automation. They will also manage privileged access controls, integrate identity telemetry into security systems, and participate in an on-call rotation.

What they look for

Identity and Access Management Okta Microsoft Entra ID CyberArk SSO MFA Conditional Access OAuth OIDC SAML SCIM PIM PAM Lifecycle Automation SIEM XDR

Requirements

Candidates must have at least 5 years of experience in IAM with hands-on proficiency in Okta, Entra ID, and PIM/PAM platforms. Strong knowledge of authentication protocols like OAuth, OIDC, and SAML is required, along with the ability to leverage AI tools for governance and automation.

Full description

Company Name

ARS-Rescue Rooter Overview

Role Summary

Builds and secures ARS identity services (Okta, Entra ID/AD, CyberArk). Implements SSO/MFA, Conditional Access, lifecycle automation, and privileged access controls for human and machine identities.

Responsibilities

Primary Responsibilities

  • Administer Okta and Entra ID/AD; implement SSO/MFA/Conditional Access and Harden admin tiers.
  • Design secure API authentication and lifecycle automation (onboarding/offboarding, SCIM/JIT).
  • Operate PIM/PAM for privileged identities—role design, approvals, JIT access, and session monitoring.
  • Integrate identity telemetry into SIEM/XDR; support access reviews and identity audits.
  • This position will participate in an on-call rotation.

Key Outcomes & KPIs

  • 100% MFA on privileged accounts; reduction in standing privilege; zero orphaned accounts.
  • Verified API auth patterns for key apps; documented Conditional Access coverage.

Qualifications

Required Qualifications

  • 5+ years in IAM; hands‑on with Okta/Entra; strong knowledge of OAuth/OIDC/SAML and SCIM provisioning.
  • Experience with PIM/PAM platforms and identity lifecycle automation.
  • AI Fluency: Demonstrated ability to leverage Claude or ChatGPT to continuously improve identity governance, access reviews, and policy automation.

Tools & Technologies

  • Okta, Microsoft Entra ID/AD, CyberArk, PIM/PAM tools, identity governance/reporting, SCIM/JIT integrations

Collaboration & Decision Rights

  • Partners with App/Infra teams on integrations; authority over identity policies and admin standards; consults with GRC on access governance and audit evidence.

ARS-Rescue Rooter is an Equal Opportunity Employer AA/EOE/M/F/V/D. In compliance with the Americans with Disabilities Act, ARS-Rescue Rooter may provide reasonable accommodations to qualified individuals with disabilities and encourages both prospective and current employees to discuss potential accommodations with the employer.

Similar roles